Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

31–40 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#31

Yes and this is a good thing. No organization, no matter how large or powerful, should be beyond the reach of the law.

That's a false dichotomy. You can hold an organization accountable to the law without requiring them to maintain a "master key" to your private data.

It isn't required.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#32

Lol it's been 20 years now that the whole world should stop to be all surprised pikachu about that.

For a long time, if you used full disk encryption, the encryption key never left your machine. If you forgot your password, the data was gone - tough luck, should have made a backup. That's still how it works on Linux. Pretty surprising they'd back up the disk encryption secrets to the cloud at all, IMHO, let alone that they'd back it up in plaintext.

Well, for a consumer notebook or mobile device, the threat model typically envisions a thief grabbing it from a coffeehouse or hotel room. So your key needs to be safeguarded from the opportunist who possesses your hardware illegally.

Linux can be fairly well-secured against state-level threat actors, but honestly, if your adversary is your own nation-state, then no amount of security is going to protect you!

For Microsoft and the other consumer-OS vendors, it is typically a bad user-experience for any user, particularly a paying subscriber, to lose access to their account and their cloud apps. There are many ways to try and cajole the naïve user into storing their recovery key somewhere safe, but the best way is to just do it for them.

A recovery key stored in the user's own cloud account is going to be secure from the typical threats that consumers will face. I, for one, am thankful that there is peace of mind both from the on-device encryption, as well as the straightforward disaster recovery methods.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#33
post #29
post #16

Apple will do this too. Your laptop encryption key is stored in your keychain (without telliing you!). All is needed is a warrant for your iCloud account and they also have access to your laptop. sixcolors.com/post/2025/09/filevault-on-macos-tahoe-no-longer-uses-icloud-to-store-its-recovery-key/

Thanks, that's good to know. I suspect WhatsApp's "we're fully E2E encrypted" would be similar too.

It's most software. Cryptography is user-unfriendly. The mechanisms used to make it user friendly sacrifice security.

There's a saying that goes "not your keys not your crypto" but this really extends to everything. If you don't control the keys something else does behind the scenes. A six digit PIN you use to unlock your phone or messaging app doesn't have enough entropy to be secure, even to derive a key-encryption-key.

If you pass a KDF with a hardness of ~5 seconds a four digit PIN to derive a key, then you can brute force the whole 10,000 possible PINs in ~13 hours. After ~6.5 hours you would have a 50% chance of guessing correctly. Six digit PIN would take significantly longer, but most software uses a hardness nowhere near 5 seconds.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#34
post #30
post #17

Earlier quoted context omitted.

Yeah, the problem is whether they already bent over for Trump admin or not yet.

Yes, I know this sounds conspiratorial, but I think the whole Liquid Ass thing was a rush to put some other software in Apple products to appease the Trump admin. For example, it is new in Tahoe that they store your filevault encryption key in your icloud keychain without telling you. https://sixcolors.com/post/2025/09/filevault-on-macos-tahoe-...

My conspiration theory about Liquid Ass is their hardware for past 5 years was so good that they needed to make people finally upgrade it. My Air M1 16GB worked absolutely fine until it slowed down immensely on macOS 26.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#35

Lol it's been 20 years now that the whole world should stop to be all surprised pikachu about that.

For a long time, if you used full disk encryption, the encryption key never left your machine. If you forgot your password, the data was gone - tough luck, should have made a backup. That's still how it works on Linux. Pretty surprising they'd back up the disk encryption secrets to the cloud at all, IMHO, let alone that they'd back it up in plaintext.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious.

"Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable traps on people are plain disconnected from reality.

Microsoft has the right approach here with Bitlocker defaults. It's not merely about UX - it's about not setting up traps and footguns that could easily cause harm to people.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#36
post #30
post #17

Earlier quoted context omitted.

Yeah, the problem is whether they already bent over for Trump admin or not yet.

Yes, I know this sounds conspiratorial, but I think the whole Liquid Ass thing was a rush to put some other software in Apple products to appease the Trump admin. For example, it is new in Tahoe that they store your filevault encryption key in your icloud keychain without telling you. https://sixcolors.com/post/2025/09/filevault-on-macos-tahoe-...

Which is a very good thing.

iCloud is much more secure than most people realize because most people don’t take the 30 minutes to learn how it is architected.

You can (and should) watch https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s for all the details about how iCloud is protected, but especially the time-linked section. :)

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#37
post #16

Apple will do this too. Your laptop encryption key is stored in your keychain (without telliing you!). All is needed is a warrant for your iCloud account and they also have access to your laptop. sixcolors.com/post/2025/09/filevault-on-macos-tahoe-no-longer-uses-icloud-to-store-its-recovery-key/

Wrong.

You can (and should) watch all of https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s for the details about how iCloud is protected by HSMs and rate limits to understand why you’re wrong, but especially the time-linked section… instead of spreading FUD about something you know nothing about.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#38
post #25

Earlier quoted context omitted.

If you have advanced data protection enabled, Apple claims: “No one else can access your end-to-end encrypted data — not even Apple — and this data remains secure even in the case of a data breach in the cloud.” https://support.apple.com/en-us/102651

Please read this section of Apple's own document before you talk about their "advanced data protection". The following information may be available from iCloud if a user has enabled Advanced Data Protection for iCloud: https://www.apple.com/legal/privacy/law-enforcement-guidelin... Do you think Tim Cook gave that gold bar to Trump for nothing?

>>Do you think Tim Cook gave that gold bar to Trump for nothing?

Not in US - THANKS for this hint: I googled it! Wow!!! The both do bribery (offering&accepting) in front of the recording camera in a government building!!

Relly "impressive" :-X

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#40
post #4

Veracrypt https://veracrypt.io/en/Home.html

https://linuxmint.com/

https://ubuntu.com/download/desktop

https://archlinux.org/

https://www.kali.org/get-kali/#kali-platforms

https://fedoraproject.org/

Every bad day for microsoft is yet another glorious day for linux.

Post reply on HN